CVE-2026-98381
Received
Received - Intake
XDP Use-After-Free in Linux Kernel Network Stack
Vulnerability report for CVE-2026-98381, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-10-09
Last updated on: 2026-10-09
Assigner: kernel.org
Description
Description
In the Linux kernel, the following vulnerability has been resolved:
veth: manage XDP program pointers during channel resize
veth_set_channels() tears down XDP resources for removed RX queues
without clearing rq->xdp_prog. If the program is then detached or
replaced, those queues keep the old pointer after bpf_prog_put().
A later channel increase can re-enable NAPI and run the freed program.
BUG: unable to handle page fault for address: ffffc90000256048
Oops: Oops: 0000 [#1] SMP KASAN NOPTI
RIP: veth_xdp_rcv_skb (include/linux/filter.h:779
include/net/xdp.h:696 drivers/net/veth.c:820)
Call Trace:
veth_xdp_rcv (drivers/net/veth.c:941)
veth_poll (drivers/net/veth.c:986)
__napi_poll (net/core/dev.c:7787)
net_rx_action (net/core/dev.c:7850 net/core/dev.c:8007)
handle_softirqs (kernel/softirq.c:645)
Kernel panic - not syncing: Fatal exception in interrupt
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| Linux | Linux | 4752eeb3d891c27905a8fdf4d80e899c0efd4ec7 |
| Linux | Linux | 4752eeb3d891c27905a8fdf4d80e899c0efd4ec7 |
| Linux | Linux | 4752eeb3d891c27905a8fdf4d80e899c0efd4ec7 |
| Linux | Linux | 4752eeb3d891c27905a8fdf4d80e899c0efd4ec7 |
| Linux | Linux | 4752eeb3d891c27905a8fdf4d80e899c0efd4ec7 |
| Linux | Linux | 4752eeb3d891c27905a8fdf4d80e899c0efd4ec7 |
| Linux | Linux | 4752eeb3d891c27905a8fdf4d80e899c0efd4ec7 |
| Linux | Linux | 5.15 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |